Impact
The vulnerability arises from the Pixeldrain crawler using substring matching for host validation instead of requiring exact domain matches. An attacker who controls a look‑alike host can supply a crafted Pixeldrain URL, which may be introduced via a third‑party site that triggers downloads for other sites. This causes the crawler to treat the fake host as supported and to send the user's Pixeldrain API key in an Authorization header to that malicious host, thus allowing the attacker to obtain the sensitive credential. This is an input validation failure (CWE‑20) that results in information disclosure (CWE‑200).
Affected Systems
Affected installations are Cyberdrop‑DL versions ranging from 8.5.0 up through, but not including, 9.14.0. Users running these versions with a Pixeldrain API key and with the Pixeldrain crawler enabled are at risk, regardless of whether the user accesses the program locally or through a third‑party site that can trigger downloads. The problem is mitigated in the 9.14.0 release.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker can construct a look‑alike domain and host a malicious site that induces users to launch Cyberdrop‑DL. If a user has the API key configured, the key will be sent to the attacker’s domain during normal operation, exposing the credential.
OpenCVE Enrichment
Github GHSA